Commit Graph

32046 Commits

Author SHA1 Message Date
talhak08 d2b0739d19 Rank's been deleted and fixed check method 2022-02-08 03:43:20 +03:00
talhak08 6955e2b4a2 Fixes 2022-02-08 03:29:49 +03:00
Talha Karakumru 274c48cf77 Microweber v1.2.10 Local File Inclusion (Authenticated) 2022-02-08 02:43:09 +03:00
Spencer McIntyre 2f3e4742f4 Land #16151, Add QEMU Monitor HMP exec module 2022-02-07 16:43:08 -05:00
Brendan Coles 5bbe934db9 Add QEMU Monitor HMP 'migrate' Command Execution module 2022-02-07 17:48:27 +00:00
Christophe De La Fuente fa849e51c3 Land #16137, Update PrintNightmare to use the moved DCERPC definitions 2022-02-07 16:54:09 +01:00
Spencer McIntyre e2c91ebf30 Land #16010, zabbix_script_exec improvements
This updates the zabbix_script_exec module to work with versions 5.0 and
newer as well as adds a new item-based execution technique.
2022-02-04 15:13:13 -05:00
Spencer McIntyre ae278d0568 Cleanup some minor typos 2022-02-04 15:12:57 -05:00
Spencer McIntyre bb94115e3a Return nil instead of failing 2022-02-04 13:12:09 -05:00
Spencer McIntyre dd64dcf074 Finish the PetitPotam module with docs 2022-02-04 13:12:08 -05:00
Spencer McIntyre 4cac9cae8d Initial commit of authenticated petit potam 2022-02-04 13:12:08 -05:00
lap1nou 8838d9cb66 Added timeout system, fixed a bug with TLS_PSK, linted 2022-02-04 04:01:23 -08:00
lap1nou 645ef5e71f Fixed few bugs 2022-02-02 14:30:02 -08:00
lap1nou 7bf08a28ea Modified default stager 2022-02-02 12:34:07 -08:00
Spencer McIntyre 7c987a452d Land #16130, Wordpress RegistrationMagic sqli 2022-02-02 10:50:13 -05:00
Spencer McIntyre dda6c53144 Fix table alignment 2022-02-02 10:48:58 -05:00
h00die ed7dc1882b updated failed login for registrationmagic 2022-02-01 17:32:34 -05:00
Spencer McIntyre 274b954c58 Land #16123, fix reference URL in cisco_ucs_rce 2022-02-01 17:06:59 -05:00
Spencer McIntyre 06fb748402 Add the missing full disclosure URL reference 2022-02-01 17:06:37 -05:00
lap1nou de32cc0e97 Linted with Rubocop, factorized API call, fixed some grammmar 2022-02-01 13:29:30 -08:00
space-r7 837fdf7c5e Land #16128, add cisco rv unauth rce 2022-02-01 10:34:57 -06:00
Spencer McIntyre b146f098a2 Update to use the moved DCERPC definitions 2022-01-31 09:03:07 -05:00
h00die b71f9e7e45 wp_plugin RegistrationMagic sqli 2022-01-30 16:08:06 -05:00
Jake Baines ccedcfefab Added exploit for CVE-2021-1472/CVE-2021-1473 2022-01-29 18:56:53 -08:00
swapnil shinde 70d4013610 fix faulty URL ref #16078 removed faulty url
fix faulty URL ref #16078 , i searched for FULL_DISC tool in Cisco but i cant find anything related to this so i removed it. if that is meant by the issue.
2022-01-29 22:33:33 +05:30
Marek Šuppa c1fefd0856 fix: Missing comma
* Fix missing comma in a list of useragents
2022-01-29 00:51:56 +01:00
adfoster-r7 c3647aa531 Land #16109, Return early if no domains are found 2022-01-28 23:34:49 +00:00
Brendan Coles b7b7cdd2d9 Nops: Add cmd/generic 2022-01-28 15:29:56 +00:00
Brendan Coles 04552d7998 windows/gather/enum_domains: Return early if no domains are found 2022-01-28 11:06:53 +00:00
bwatters f3f3f8726c update payload cache sizes 2022-01-27 09:18:08 -06:00
agalway-r7 0e0834302d Land #16099, cleans up smb_relay module via rubocop 2022-01-26 10:28:52 +00:00
adfoster-r7 a17dfcc849 Rubocop smb relay module 2022-01-26 00:47:19 +00:00
Grant Willcox 44f040ad78 Land #16056, Exploit Module for Grandstream UCM62xx IP PBX (CVE-2020-5722) 2022-01-24 21:03:46 -06:00
Grant Willcox 15751a0f78 Minor langauge fix and final typo 2022-01-24 21:01:34 -06:00
Spencer McIntyre 3cd2b1b929 Update naming for consistency and the module 2022-01-24 10:35:40 -06:00
Jake Baines 04d06a2df1 Switched to proper fail_with calls in exploit failure 2022-01-24 04:13:43 -08:00
Jake Baines 2c989ec714 Addressed multiple review comments (spelling, doc details, randomization, etc) 2022-01-22 14:09:58 -08:00
Grant Willcox d064bbe9a5 Land #16053, Log4Shell Unifi Controller RCE 2022-01-21 12:51:38 -06:00
Spencer McIntyre 458d584f83 Add details to check codes and PR feedback 2022-01-21 09:40:23 -05:00
Grant Willcox 1186529204 Land #16020, Adding Modbus Service Device ID 0x2B 2022-01-20 12:53:37 -06:00
Grant Willcox 05fe2fadbb Apply RuboCop rules to modbusclient.rb 2022-01-20 12:23:01 -06:00
Grant Willcox 577f5f81b9 Fix up spacing errors and fix a potential OOB reference issue 2022-01-20 12:14:51 -06:00
VanSnitza 899fbfcb85 Update modbusclient.rb 2022-01-20 17:36:02 +01:00
VanSnitza b3fb678055 Update modules/auxiliary/scanner/scada/modbusclient.rb
Co-authored-by: Grant Willcox <63261883+gwillcox-r7@users.noreply.github.com>
2022-01-20 17:16:24 +01:00
Spencer McIntyre 579627f5c7 Update docs, note OS X support 2022-01-20 10:47:11 -05:00
VanSnitza 2f76c602f2 Update modbusclient.rb 2022-01-20 16:37:11 +01:00
Spencer McIntyre ba469a4b2c Add version detection to the Unifi exploit 2022-01-20 09:26:48 -05:00
Brendan Coles a31052afbd post/multi/manage/sudo: Abort if session type is Meterpreter 2022-01-20 12:44:29 +00:00
VanSnitza 0765b1ffb1 Update modules/auxiliary/scanner/scada/modbusclient.rb
Co-authored-by: Grant Willcox <63261883+gwillcox-r7@users.noreply.github.com>
2022-01-20 11:42:06 +01:00
Spencer McIntyre 3d80a46e67 Check the HTTP response from the trigger 2022-01-19 17:51:31 -05:00